Refuse the send the record cannot support: stage the audience, test it against suppression and the frequency cap at the hour of release, and leave that release to a named marketer.
A list is uploaded, and a contact who unsubscribed in March can re-enter the audience in June.
02
A send is staged, and the audience meets suppression at that moment, not when the list was built.
Reason
03
A segment is assembled from inferred attributes, and it says on its face that it was inferred.
04
A send leaves, and there is no recall — which is why the release gate is the whole product.
05
An email and a text draw on one audience, and the cap you set is applied across both channels.
Decide
06
A footer is drafted, and 16 CFR Part 316 wants a working opt-out and a physical postal address.
07
A bounce signal moves, and it describes the state of a list rather than granting any permission.
Out
08
A sync runs overnight, and each synced list is a fresh re-entry risk until suppression clears it.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent assembles the audience, tests it against suppression and the frequency cap at send time, and drafts the send. A named marketer releases it — nothing in CAN-SPAM is signed or certified.
2Audience context assembledThe segment, the list it came from, the channels it reaches and the hour of release
3Send package draftedThe audience, its suppression state, the caps it consumes and completeness
4Controls appliedSuppression checks, frequency checks, footer checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is released at any of them — the agent is staging, and the compliance lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Goes to the named marketer to release.
Anything thin
Adds a compliance analyst read first.
Compliance review
The send is held with its audience, its suppression state and the caps behind it.
Release · Append evidence · Send to compliance
Released — by a named marketer▼
6Suppression and send records updatedOnly where write access and records policy allow it
7Outcome evaluatedSuppression integrity, cap adherence, analyst corrections and what the read found
Corrections
Every analyst correction is carried into the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Releasing a send to a live audience.
Deciding a revocation was validly made.
Certifying anything about a consent record.
Setting the frequency cap a brand sends under.
Automation boundaryAgent acts unaided
✓Assemble the audience from the segments your brief actually names.
✓Re-test the staged audience against suppression.
✓Draw email and text against one shared frequency budget per contact.
✓Surface the bounce, complaint and authentication.
Nothing is released or sent except by a named person, inside the agreed boundaries.
Judging whether a suppression file is complete.
Answering a regulator about a past campaign.
Deciding which audience a campaign may reach.
Changes to suppression, audience or send records.
Example output
One send, annotated
Our sibling consent and revocation evidence agent owns the consent record, the revocation intake, the honouring clocks and the litigation evidence file; this page assembles no consent evidence and adjudicates no revocation — it refuses to send what the record cannot support.
Send record · single releaseIllustrative example
Send
Recorded as
Channel
Evidence of record
Confidence
Held for
Reactivation send, uploaded list
Tested against suppression at staging
Email and SMS
List import, 3 August 2026
Held unreleased
The releasing marketer, by name
As receivedTaken from the import log and the suppression file — it reaches as far as those sources do.
What the record holdsSuppression check logImport provenanceFrequency budget trail
Why no send hereWhether an audience may be sent at all is a marketer call, not a model output.
ActionReleaseAppend evidenceSend to compliance
What the score decidesBelow the configured threshold a send picks up a compliance read before the marketer sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every sendFrom the list it drew on
03Evidence
Where the evidence is used
Our advertising pages are agency-side and bill a client for the media; this one answers to the brand legal, privacy and finance functions that live with the list long after a campaign ends.
01Approved path
The send is the last gate
A suppression list is only as good as the last import, so an assembled audience is tested at the moment of release rather than when the list was built.
02Human review
What was checked, and not found
The 1 August 2026 amendment shown against the CAN-SPAM rule was not read back to primary text; nothing under it is signed, filed or certified, so no filing record exists to inspect; no authority publishes a bounce, complaint or authentication threshold that would make a list fit to send; and no sending platform documents how its own list sync behaves against an existing suppression file.
04Build an evidence trail
The send, the audience it drew on and the marketer who released it stay on file.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Sending platformsEmail service providers · SMS gateways Send and suppression logs
Audience sourcesCRM · CDP · uploaded and synced lists Segment and list records
Deliverability signalsBounce, complaint and authentication feeds List health records
Agent
Email and SMS campaign
Assembles the audience Tests it at send time Holds for the marketer
Records and case systemsPreference centre · ticketing Cap and release records
Integration availability depends on the client's existing systems and API access.
Agent controls
Six shutters between the model and the marketer
Six shutters closing in order, the last the tightest. What still gets out is set out in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to audience assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and suppression rules; a rule amended after the last import is the one that lets a contact back in.Track
L4TraceabilityRecord each send, the audience behind it, the suppression state it met and every read of that record.Record
L3Marketer releaseHold the send for a named marketer; the hold governs release, not whether the underlying permission was ever valid.Gate
L2Send guardrailsTest each staged send against your suppression file, your frequency cap and the footer mechanics 16 CFR Part 316 sets: a working opt-out and a physical postal address.Restrict
L1Confidence thresholdsRoute a thin audience to a compliance read first; a segment built on inferred attributes has to declare the inference.Require review
Model coreEvidence assembled — the audience, its suppression state, the caps and completeness
L1 – L2Test whether a send may go
L3Puts the release in a person's hands
L4 – L5Keep the send and the audience behind it
L6Holds the send unreleased when signals degrade
How Nestack evaluates it
Evaluate the whole assembly — not only the send package that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the message a recipient receives
Depth of coverage ▼
E1Final-output evaluationDid the send reach only the audience it was cleared for?
E2Step-level evaluationDid the agent read the right list, the right cap and the live suppression state?
E3Tool evaluationDid it read and write the correct audience and the correct suppression file?
E4Confidence calibrationDo low-confidence audiences actually attract more compliance corrections?
E5Slice evaluationHow does performance change across specific list sources?
E6Business outcomeHow many sends needed a correction before the marketer released?
Floor — the audience the brand answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each placed at the stage where it first shows.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
KZ-03
Stale audience read
The audience read is not the one now staged.
Stage gathersThe lists, the contacts, the caps and the sends
02 · Reasoning2 modes
KZ-04
Suppression assumed, not tested
An audience moves on without a send-time check.
KZ-06
Cap read from one channel
Email and text are budgeted apart, not together.
Stage proposesThe audiences, their caps and suppression state
03 · Tool / write2 modes
KZ-02
Thin audience passed forward
A staged send skips the compliance read.
KZ-05
Bound to the wrong list
A suppression entry lands on the wrong contact.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
KZ-01
Released, audience unrecorded
A send sits on file with no audience behind it.
Stage returnsThe send a marketer releases and a recipient opens
05 · Change / Version1 mode
KZ-07
Silent suppression regression
A platform change moves the audience, not the record.
Stage tracksModel, prompt, suppression rules and send fields
Sev-1 · a send to a suppressed contactSev-2 · wrong audience reaches the sendSev-3 · source degrades, send held back
A send-level suppression-integrity figure can read clean while uploaded and synced lists carry most of the rework. Nestack reports the correction rate by list source, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Uploaded and synced lists
10.9%
3.6×
Review
Partner and co-registration feeds
7.8%
2.6×
Review
Behaviour-triggered sends
4.9%
1.6×
Watch
Native sign-up capture
1.8%
0.6×
Normal
Bar: correction-rate lift vs. native sign-up baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What an unsuppressed send costs
A loop ends when the resurrected contact has become a case the next release must pass. That suite is what the next send cleared is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on uploaded and synced lists.
02Diagnose
The contact who unsubscribed in March and reappeared in an uploaded list in June is traced back until a single cause is left.
03Improve
Number the change; the sends that drove it are filed underneath it.
04Verify
Each touched send case is run once more, and one red holds it back.
05Learn
It stays on as a standing test, and the suppression rules travel with it.
Learn → DetectThe return edge. The next send is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, audience assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Suppression-integrity discovery and boundary work.
02List, platform and delivery sources.
03Send-to-suppression and frequency-budget mapping.
04Audience and suppression ingestion.
05Contact, list and send binding.
06Completeness scoring and review routing.
07Marketer release workflow.
08Send-platform and CRM integration.
09Suppression and footer cases.
10Guardrails and send controls.
11Send-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne list source, one send yearProductionProduction send workflowAdvancedMultiple brands / regions
Introduced at Pilot
Audience assembly to your lists✓✓✓
Named marketer release✓✓✓
Addressable-audience baseline✓✓✓
Introduced at Production
Reporting by send—✓✓
Release workflow in your systems—✓✓
Approved write-back—✓✓
Platform-and-list integration—✓✓
Introduced at Advanced
Multi-region estates——✓
Cross-channel release packs——✓
Large sending volumes——✓
Multi-channel frequency controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, send volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your sending platforms and the lists behind them→List inventory mapping and suppression captureWeek 1
02Representative sends, imports and suppression files→Record binding, cap logic and the suppression baselineWeek 2
03Your frequency caps and the channels they cover→List mapping, cap binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Platform, list and deliverability source assessment, then integration setupWeek 2
05Sends you would not want recalled→Suppression cases and the evaluation runWeek 4
06What no send record may settle→Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named marketer to release the send→Release workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The widths are weeks of actual work rather than layout, which is why one band has to carry two.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Campaign workflow discovery, list mapping and the automation boundaryW2Source integration and the suppression-integrity baselineW3Audience assembly, cap logic and release controlsW4Evaluation suite, suppression cases and failure-mode testingW5Platform integration, pilot sends and targeted correctionsW6One campaign year run under the lifecycle lead, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth takes a pair because the work does.
At the end of W6When the send record validates, Agent Care takes the agent on.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Marketing AI agent
Build a campaign send agent around the contact who unsubscribed in March and came back on a list in June.
Show us one staged send and the list it drew on. A named marketer releases it, never the agent. Suppression is tested at the hour of release rather than at list build, and nothing in CAN-SPAM is signed or certified. Consent capture and revocation intake are a different agent.